Sam Tunick didn't strike a blow for civil liberties when he deployed a duress password against federal agents. He just shipped a terrible onboarding flow.
When the news broke that the US government was prosecuting American citizen Sam Tunick for allegedly handing over a duress password that systematically wiped his phone during a January 24th border stop at Hartsfield-Jackson airport, the tech press predictably lost its mind. The discourse immediately devolved into low-leverage debates about the Fifth Amendment, civil liberties, and the supposedly dystopian overreach of federal agents demanding full access to a traveler's digital life. But as someone who has spent the last decade building consumer products at scale, I couldn't help but look at the situation and feel a profound sense of secondhand embarrassment. Tunick didn't strike a blow for freedom. He just shipped a fundamentally hostile user experience.
If we break down a secondary screening at customs from first principles, what is it, really? It is an onboarding flow. The federal agent is the user, the traveler's device is the platform, and the goal is a seamless, zero-friction data exchange that results in a verified entry state. When agents pulled Tunick aside in Atlanta to reportedly ask him about child exploitation images, they were simply initiating an API call to his personal stack. By intentionally providing a duress password that triggered a factory reset, Tunick didn't just deny a permissions request. He deployed a malicious breaking change that crashed the client mid-session.
Consider the timeline of the January 24th incident. The agents initiated the engagement. They established a clear enterprise priority. Tunick was given the prompt. Instead of returning the expected array, he typed in a secondary string that executed a scorched-earth script across his entire device. This isn't protecting your digital footprint. This is deploying ransomware against the people who manage the physical perimeter of the country.
Think about the sheer arrogance of that design choice. You have a highly motivated user standing right in front of you, actively trying to engage with your product. They are leaning in. They are literally detaining you in a windowless room to maximize their focus on your content. And instead of serving them the requested data payloads, you intentionally brick the ecosystem. It is the definition of a dark pattern.

I was discussing this over matcha in Hayes Valley yesterday with a former founder who now consults for the Department of Homeland Security, and we both agreed that the duress code is a cowardly feature. Great products are built on a foundation of interoperability and radical transparency. When you build a self-destruct mechanism into your lock screen, you are signaling to the market that you do not believe in your own data. You are optimizing for churn. If your digital footprint is so fragile that it cannot withstand a basic audit by heavily armed personnel, you need to pivot your lifestyle.
The government's decision to formally charge Tunick is, frankly, a necessary market correction. For too long, we have treated federal investigators as adversarial actors rather than key enterprise stakeholders. When a user experiences a total data wipe during a routine onboarding questionnaire, they are going to churn, and in the case of Customs and Border Protection, churning means they indict you.
We have to design for the reality of the ecosystem we live in, not the utopian privacy sandbox we wish we inhabited. This is why I am so bullish on the decision to prosecute. It sends a clear signal to the community that you cannot simply opt out of the state's data-gathering apparatus just because it introduces some friction into your personal roadmap.
We are constantly iterating on our intake funnels to reduce friction, but when a traveler deliberately triggers a catastrophic data wipe, it completely ruins our daily active user metrics.
Hollister is entirely right to be frustrated. Imagine the wasted compute. You have multiple highly salaried agents, the overhead of the Atlanta airport facility, and the latency of the physical detention process, all completely bottlenecked because one citizen decided to be precious about their local storage. In any other industry, intentionally destroying the deliverables during a vendor review would get you sued by your investors. Here, it gets you charged with a federal crime, which is really just the public sector's version of a clawback clause.
My advice to anyone traveling internationally right now is to treat your lock screen as a landing page. When you hand your unlocked phone to a federal agent, you are giving them their first impression of your personal brand. You should want that experience to be delightful. Organize your apps. Curate your photo albums so the agent doesn't have to scroll past your breakfast pictures to get to your financial disclosures. Make their job easier, and they will make your transit faster.
Tunick's legal team is currently filing motions to fight the charges, clinging to outdated regulatory frameworks like the Constitution. It is a classic incumbent mistake, trying to legislate your way out of a product failure. The reality is that the duress password is already deprecated. The smartest people I know are already building for a post-privacy paradigm, where automated device-mirroring creates a truly frictionless border experience. If you want to succeed in today's hyper-connected environment, you have to stop fighting the API and start optimizing your payloads for the people who own the physical infrastructure. Otherwise, you're just another deprecated asset waiting to be wiped.